The Georgia billing firm took eight months to determine what was taken, and the files are now freely downloadable rather than sold.
What happened
MCBS, LLC, a medical billing and coding company based in Augusta, Georgia, is notifying 1,261,464 people that their information was taken in a 2025 intrusion, according to the HHS Office for Civil Rights breach portal. The company detected unauthorized network access on or about September 25, 2025, and its investigation established that an unauthorized user may have accessed or removed files between September 22 and September 26, MCBS said in its public notice. A ransomware group calling itself PEAR, short for Pure Extraction and Ransom, claimed the attack and put the stolen material on its leak site, where it is available for anyone to download rather than offered for sale, BleepingComputer reported. The group put the archive at 3.3 terabytes.
Going deeper
Determining what the files contained took MCBS until May 28, 2026, roughly eight months after detection, following what the company describes as a manual review of the affected data. The categories it identified run through nearly everything a billing operation holds, covering names, addresses, Social Security numbers, dates of birth, health plan beneficiary numbers, insurance policy and subscriber identification numbers, medical history, mental or physical condition, treatment information, and diagnosis information. Seven covered entities are named in the notice as affected: C&C MD PC, Nuclear Medicine and Pathology Associates, Radiation Oncology Associates, SkinPath Solutions, South Georgia Radiology Consultants, Stephen W. Brown & Radiology Associates of Augusta, and Vascular Radiology Associates II. The specialties involved carry their own disclosure problem, since a billing record naming a radiation oncology practice reveals a cancer diagnosis without any diagnosis code being read.
What was said
"We have no evidence of any identity theft related to this incident," MCBS stated in its notice, while reminding individuals to review financial account statements regularly for fraudulent activity. The company added that it contained the incident immediately upon detection, engaged cybersecurity experts to identify what personal information was involved, and continues to evaluate and modify its practices.
In the know
PEAR surfaced in mid-2025 and posted its first batch of victims that August, operating on a model that skips encryption entirely in favor of stealing data and charging for its deletion. Healthcare is its primary sector alongside business services, manufacturing, and technology, and researchers who have investigated its attacks counted at least 51 victims by February 2026, with ransom demands averaging around $550,000, BankInfoSecurity reported. Initial access typically comes through compromised virtual private network credentials, and rather than deploying custom malware, the group installs legitimate remote management software such as AteraAgent and Splashtop Remote Service, which administrators use routinely and security tools rarely question. Its healthcare victims include Tri-Century Eye Care, Think Big Health Care Solutions, and Brevard Skin and Cancer Center, a mix of direct care providers and vendors serving them.
The big picture
Publication without sale changes what victims face. Data offered on a criminal market reaches whoever pays, while data posted for open download reaches anyone who looks, including people running phishing campaigns who now hold names, diagnoses, insurers, and policy numbers for the same individuals. Notification letters advising recipients to watch their credit address the identity theft risk and not the medical or reputational exposure, and a credit freeze does nothing about a cancer treatment history circulating in a public archive. For the seven practices named, each carries its own analysis under the Breach Notification Rule, where publication removes any argument that the information was not actually acquired. Practices contracting with billing vendors should establish now whether their agreements require notification within days rather than at the vendor's convenience, since eight months passed here between detection and a determination of what was taken.
FAQs
Why would a criminal group publish data instead of selling it?
Free publication punishes non-payment and demonstrates to future victims that refusing carries consequences, which supports the group's leverage in later negotiations. Selling requires finding buyers and handling transactions, while publishing costs nothing and generates the attention that pressures the next target.
What does it mean when attackers use legitimate remote management software?
Tools such as remote support agents are installed across most corporate networks for genuine administration, so their presence raises no alarm and antivirus software does not flag them. Detection depends on knowing which of these tools your organization actually uses and alerting when a different one appears.
Does a billing vendor breach expose clinical information even without medical records?
Yes. Claims data contains diagnosis codes, procedure codes, treatment dates, and the identity of the treating practice, which together describe a person's medical situation in detail. The specialty of the practice alone can disclose a condition the patient never discussed outside a clinical setting.
How should a practice assess a billing vendor's security before contracting?
Ask which remote access methods are permitted and whether multifactor authentication protects all of them, how many client practices share the same environment, what monitoring covers data leaving the network, and how quickly the vendor commits to notifying clients. Detection and notification timing belong in the contract rather than in a questionnaire.
What can patients do when medical information rather than financial data is exposed?
Less than with financial identifiers, which is the practical difficulty. Reviewing explanation of benefits statements for services they did not receive catches medical identity theft, and requesting a copy of their records from the treating practice establishes a baseline if entries are later added fraudulently.
